← Back

CVE-2014-2241

nvd nist
Published: Mar 18, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.

Affected (4)

1 product
Freetype
1 product
Ubuntu Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Freetype
Up to 2.5.2
Version 2.5.1
Version 2.5
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 13.10

References (10)

Timeline

No history available yet.